Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Contrast Security Protect comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Vulnerability Management (23rd), Container Security (22nd), Static Code Analysis (3rd), API Security (4th), Dynamic Application Security Testing (DAST) (4th), DevSecOps (4th), Risk-Based Vulnerability Management (9th)
Contrast Security Protect
Ranking in Application Security Tools
30th
Average Rating
8.4
Reviews Sentiment
5.8
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Application Security Tools category, the mindshare of Checkmarx One is 10.3%, down from 13.9% compared to the previous year. The mindshare of Contrast Security Protect is 0.6%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Akshay Waghmare - PeerSpot reviewer
A stable DevSecOps product that gives fewer false positives
We use the product for DevSecOps.  The product gives a few false positives. We get 99 percent true positives.  Contrast Security Protect needs to improve integration.  I have been using the product for a year.  Contrast Security Protect is stable.  The solution is scalable. My company has ten…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The only thing I like is that Checkmarx does not need to compile."
"It is a stable product."
"The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
"The main benefit to using this solution is that we find vulnerabilities in our software before the development cycle is complete."
"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code."
"The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
"The user interface is excellent. It's very user friendly."
"Protect provides us with more in-depth visibility into ongoing attacks."
"The solution has excellent real-time capabilities."
"The product gives a few false positives. We get 99 percent true positives."
 

Cons

"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"We can run only one project at a time."
"Checkmarx could be improved with more integration with third-party software."
"The plugins for the development environment have room for improvements such as for Android Studio and X code."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"Checkmarx needs improvement in its Dynamic Application Security Testing (DAST) and API security features."
"Checkmarx is not good because it has too many false positive issues."
"They could work to improve the user interface. Right now, it really is lacking."
"Protect's reporting GUI is very basic. To get all statuses from the APIs, we needed to write our own KPI dashboard to provide reports."
"Contrast Security Protect needs to improve integration."
"There's room for improvement in the initial setup."
 

Pricing and Cost Advice

"The solution is costly."
"Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"We have purchased an annual license to use this solution. The price is reasonable."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
Information not available
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
865,164 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Financial Services Firm
26%
Manufacturing Company
14%
Insurance Company
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Contrast Security Protect?
The product gives a few false positives. We get 99 percent true positives.
What needs improvement with Contrast Security Protect?
Contrast Security Protect needs to improve integration.
 

Also Known As

No data available
Contrast Protect
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Williams-Sonoma, Autodesk, HUAWEI, Chromeriver, RingCentral, Demandware.
Find out what your peers are saying about Checkmarx One vs. Contrast Security Protect and other solutions. Updated: July 2025.
865,164 professionals have used our research since 2012.